Survey of Machine Learning Techniques for Malware Analysis
arXiv:1710.08189 · doi:10.1016/j.cose.2018.11.001
Abstract
Coping with malware is getting more and more challenging, given their relentless growth in complexity and volume. One of the most common approaches in literature is using machine learning techniques, to automatically learn models and patterns behind such complexity, and to develop technologies to keep pace with malware evolution. This survey aims at providing an overview on the way machine learning has been used so far in the context of malware analysis in Windows environments, i.e. for the analysis of Portable Executables. We systematize surveyed papers according to their objectives (i.e., the expected output), what information about malware they specifically use (i.e., the features), and what machine learning techniques they employ (i.e., what algorithm is used to process the input and produce the output). We also outline a number of issues and challenges, including those concerning the used datasets, and identify the main current topical trends and how to possibly advance them. In particular, we introduce the novel concept of malware analysis economics, regarding the study of existing trade-offs among key metrics, such as analysis accuracy and economical costs.
55 pages, 4 figures, 8 tables, added new references, corrected typos, and revised manuscript. Forthcoming in Computers & Security
References in corpus (3)
Cited by in corpus (37)
- Explainable Artificial Intelligence Applications in Cyber Security: State-of-the-Art in Research
- The Role of Machine Learning in Cybersecurity
- Adversarial Attacks against Windows PE Malware Detection: A Survey of the State-of-the-Art
- Deep Learning for Android Malware Defenses: a Systematic Literature Review
- Fusing Feature Engineering and Deep Learning: A Case Study for Malware Classification
- A Survey on Cross-Architectural IoT Malware Threat Hunting
- Deep Multi-Task Learning for Malware Image Classification
- Malytics: A Malware Detection Scheme
- Creating Valid Adversarial Examples of Malware
- Evaluating the Potential of Quantum Machine Learning in Cybersecurity: A Case-Study on PCA-based Intrusion Detection Systems
- A Comprehensive Study on Learning-Based PE Malware Family Classification Methods
- A survey on hardware-based malware detection approaches
- Quo Vadis: Hybrid Machine Learning Meta-Model based on Contextual and Behavioral Malware Representations
- Exploring Optimal Deep Learning Models for Image-based Malware Variant Classification
- A survey on practical adversarial examples for malware classifiers
- A Survey on Machine Learning Techniques for Source Code Analysis
- Collective Intelligence: Decentralized Learning for Android Malware Detection in IoT with Blockchain
- Combating Concept Drift with Explanatory Detection and Adaptation for Android Malware Classification
- KiNETGAN: Enabling Distributed Network Intrusion Detection through Knowledge-Infused Synthetic Data Generation
- Combining Generators of Adversarial Malware Examples to Increase Evasion Rate
- Tarallo: Evading Behavioral Malware Detectors in the Problem Space
- Towards an Automated Pipeline for Detecting and Classifying Malware through Machine Learning
- Improving type information inferred by decompilers with supervised machine learning
- PhishingHook: Catching Phishing Ethereum Smart Contracts leveraging EVM Opcodes
- ClarAVy: A Tool for Scalable and Accurate Malware Family Labeling
- Learning Malware Representation based on Execution Sequences
- Neurlux: Dynamic Malware Analysis Without Feature Engineering
- Malware Classification Using Deep Boosted Learning
- LLM-Generated Samples for Android Malware Detection
- Comparative Review of Malware Analysis Methodologies
- Ten AI Stepping Stones for Cybersecurity
- Being Single Has Benefits. Instance Poisoning to Deceive Malware Classifiers
- A Survey on Common Threats in npm and PyPi Registries
- Quantum Computing Methods for Malware Detection
- Uncovering Black-hat SEO based fake E-commerce scam groups from their redirectors and websites
- Zipf-Gramming: Scaling Byte N-Grams Up to Production Sized Malware Corpora
- Malware Detection and Analysis: Challenges and Research Opportunities